0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

npm v12 Implements Security Defaults: Blocked Install Scripts, Git Dependencies, Remote URLs (infosecurity-magazine.com)

· 45d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • npm v12 blocks install scripts, Git dependencies, and remote URLs by default.
  • Developers can test warnings with npm 11.16.0+ and use `npm approve-scripts`.
  • Experts warn of potential attack pivot to private repos and risk of blind approval.

"GitHub announced npm v12, introducing three security-focused breaking changes to combat software supply chain attacks. Available from July 2026, the update will block automatic execution of install scripts, prevent resolving dependencies from custom Git URLs, and forbid sourcing packages from external URLs by default. Developers can prepare using npm 11.16.0+ to receive warnings and use the `npm approve-scripts` command. Security experts comment that while the changes close common attack vectors, they may shift attackers to private repositories and create friction that could lead to blind approval of scripts."

Discussion Matrix

0 segments

no comments yet.